Usable with caveats: the package is licensed, documented, tested, and not deprecated, but it has had no release or repository activity since January 2023. Its single-maintainer project has very little adoption and no security policy, so long-term support is uncertain.
58%
Total Score
50
50
72
83
Only three releases were published, all around January 2023, with no release in the following years. That limited history and prolonged release gap reduce confidence in ongoing maintenance.
There were zero commits and zero active maintainers in the last three months, consistent with the long release gap and creating a substantial abandonment risk.
The package has six runtime dependencies, including the Hyperf framework and Elasticsearch client, creating meaningful dependency surface area but not an inherently unhealthy profile.
Only one registry account has publish access, leaving little publishing redundancy. The linked repository is user-owned, so this is a genuine support-capacity concern rather than normal organization publishing hygiene.
There are no open issues or pull requests and no recent issue or pull-request activity. This is not inherently bad, but alongside the absent commits it provides no evidence of active maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/cache Version * | — | — |
hyperf/utils Version * | — | — |
hyperf/framework Version * | — | — |
hyperf/paginator Version * | — | — |
elasticsearch/elasticsearch Version ^8.5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.